WeblogicÔÙ±¬¸ßΣ·ì϶ 8827Ì«Ñô¼¯ÍÅÌṩ½â¾ö¹æ»®

°ä²¼¹¦·ò 2019-10-17
2019Äê10ÔÂ15ÈÕ£¬£¬£¬£¬£¬£¬Oracle¹Ù·½°ä²¼10Ô·ݰ²È«²¹¶¡, ÆäÖÐÔ̺¬ÁË8827Ì«Ñô¼¯ÍÅADLab·¢ÏÖ²¢Ìá½»¸ø¹Ù·½µÄÁ½¸ö°²È«·ì϶¡£¡£¡£¡£¡£¡£¡£¡£



CVE-2019-2890 £¬£¬£¬£¬£¬£¬¹¥»÷Õß¿Éͨ¹ýT3ºÍ̸¶Ô´æÔڸ÷ì϶µÄWebLogic×é¼þÖ´ÐÐÔ¶³ÌËÁÒâ´úÂë¹¥»÷£»£»£»£»£»£» £»£»


CVE-2019-2887£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÄܹ»ÔÚδÊÚȨµÄÇé¿öÏÂͨ¹ýT3ºÍ̸¶Ô´æÔڸ÷ì϶µÄWebLogic×é¼þ½øÐÐÔ¶³ÌBlind XXE¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


·ì϶ӰÏì°æ±¾



WebLogic Server 10.3.6.0
WebLogic Server 12.1.3.0
WebLogic Server 12.2.1.3



·ì϶ÀûÓÃ



°²È«·ì϶£ºCVE-2019-2890
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

°²È«·ì϶£ºCVE-2019-2887
²âÊÔ»·¾³£ºWebLogic Server 10.3.6.0
·ì϶ÀûÓóÉЧ:  

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



½â¾ö¹æ»®



? Éý¼¶¹Ù·½²¹¶¡
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html

? ²úÆ·¼ì²âÓë·À»¤
ÒѲ¿Êð8827Ì«Ñô¼¯ÍÅIDS¡¢IPS¡¢WAF²úÆ·µÄ¿Í»§ÇëÈ·ÈÏÈçÏÂÊÂÎñ¹æ¶¨ÒѾ­Ï·¢²¢ÀûÓ㬣¬£¬£¬£¬£¬¼´¿ÉÓÐЧ¼ì²â»ò×è¶Ï¹¥»÷£º 


TCP_Oracle_WebLogic_·´ÐòÁл¯·ì϶[CVE-2019-2890] 
HTTP_WebLogic_XXE×¢Èë·ì϶[CVE-2019-2887]

£¨1£©ÌìãÙÈëÇÖ¼ì²âÓëÖÎÀíϵͳ±¨¾¯½ØÍ¼£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½ØÍ¼£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

£¨3£©ÌìÇåWebÀûÓð²È«Íø¹Ø±¨¾¯½ØÍ¼£º

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


·ì϶ɨÃè


8827Ì«Ñô¼¯ÍÅÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0ÓÚ2019Äê10ÔÂ17ÈÕ´¹Î£°ä²¼Õë¶Ô¸Ã·ì϶µÄÉý¼¶°ü£¬£¬£¬£¬£¬£¬Ö§³Ö¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬£¬£¬£¬Óû§Éý¼¶Ì쾵©ɨ²úÆ··ì϶¿âºó¼´¿É¶Ô¸Ã·ì϶½øÐÐɨÃè¡£¡£¡£¡£¡£¡£¡£¡£


6070°æ±¾Éý¼¶°üΪ607000250£¬£¬£¬£¬£¬£¬Éý¼¶°üÏÂÔØµØÖ·£º
/article/type/1/146.html

ÇëÌì¾µ´àÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬£¬£¬£¬£¬£¬ÊµÊ±¶Ô¸Ã·ì϶½øÐмì²â£¬£¬£¬£¬£¬£¬ÒԱ㾡¿ì²ÉÈ¡·À±¸´ëÊ©¡£¡£¡£¡£¡£¡£¡£¡£

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website

8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website